New Ivake now replies to new enquiries, checks documents and chases unpaid fees on its own. See how it works
Platform
Solutions
Resources

Your school is a Data Fiduciary. Most principals do not know it yet

The Digital Personal Data Protection Act treats a school like any other organisation holding personal data — except that almost every person whose data you hold is a child, which is the strictest category the Act has.

When the DPDP Act passed, most Indian schools reasonably assumed it was about technology companies. It is not. It applies to any organisation that processes personal data digitally, and a school holds more sensitive personal data per person than most businesses ever will — names, addresses, photographs, medical notes, caste and income certificates, marks, attendance, fee history and a parent's phone number.

And every one of those records belongs to a child.

The short versionYour school is the Data Fiduciary — legally accountable for that data. Your software vendors are Data Processors acting on your instructions. Their compliance does not transfer to you. If a parent complains or a regulator asks, the school answers.

Who is who

Data Principal the child, and the parent who consents data Your school Data Fiduciary accountable instructions Data Processors Your ERP or SIS Payment gateway SMS and WhatsApp Transport tracking accountability comes back to you, whatever the vendor promised

The dashed line is the one schools miss. You can delegate the processing. You cannot delegate the responsibility.

Why children change everything

The Act sets a materially higher bar for anyone under eighteen. Three obligations matter most to a school.

Verifiable parental consent

Consent for a child's data has to come from a parent or guardian, and it has to be verifiable — you must be able to show it was genuinely them. A tick box on a paper form filled in at admission, with no record of who ticked it or when, is weak evidence. A signature you cannot produce four years later is no evidence at all.

No behavioural tracking or targeted advertising at children

This is unambiguous and it catches schools by surprise, because the tracking is usually not theirs. If your school website or parent portal carries advertising pixels, or an analytics tool that profiles individuals, that is a problem. Most schools have never audited what is embedded in their own site.

Purpose limitation, which is where alumni outreach gets caught

Data collected to educate a child is collected for that purpose. Using the same contact list years later to market a new campus, or passing it to an affiliated institution, is a different purpose and generally needs fresh consent. Schools do this routinely without thinking about it.

The four questions you cannot currently answer

Try these on your existing systems. Most schools fail at least three.

  • What exactly did this parent consent to, and when? Not "we have a form" — the specific purposes, the date, and evidence it was them.
  • Where is all of this child's data? Across the ERP, the WhatsApp group, the transport app, the photographer's folder and three teachers' phones.
  • Can you delete it if asked? And do you know which parts you are legally required to keep regardless — because academic records generally must be retained, and erasure does not override that.
  • Who else has it? A named list of every vendor that touches student data, and what each one does with it.
The gap is rarely bad intent. It is that consent was collected on paper, data spread across tools nobody inventoried, and no one was ever asked to prove any of it.

What a breach obligation actually means

If personal data you hold is exposed — a lost laptop, a misconfigured drive, a staff account taken over — you have reporting obligations, to the Data Protection Board and to the people affected. Those are parents of children.

The practical requirement behind that is unglamorous: you must be able to say what was exposed and whose. A school whose student data lives in one system with an audit trail can answer in hours. A school whose data is spread across spreadsheets, shared drives and personal devices may never be able to answer at all, which is its own kind of failure.

Six things worth doing this term

  1. Write down what you hold and why. One page per category — admission, academic, medical, financial, images. Purpose, who can see it, how long you keep it. This is the foundation of everything else.
  2. Audit your own website. Open it and look at what loads. Advertising pixels and individual-level analytics on a school site aimed at children are the easiest thing on this list to fix and the most likely to be there.
  3. Move consent to the point of collection. Captured digitally, with the purpose recorded alongside it and a timestamp, so it can be produced later.
  4. List your processors by name. Every vendor touching student data. If you cannot complete the list from memory, that is the finding.
  5. Ask each vendor for their DPA. A processor who cannot produce a data processing agreement, a sub-processor list and a retention position is a risk you are carrying on behalf of your students.
  6. Deal with WhatsApp groups honestly. Class groups run on personal numbers, with photographs of children, outside any system you control. Everyone knows this. Very few have decided what to do about it.

None of that needs a consultant to begin. It needs somebody named as responsible and an afternoon.

If you do one thingList every place a student's personal data currently lives, including the informal ones. You cannot protect, produce or delete what you have not admitted you hold — and the list is almost always longer than a principal expects.

This describes obligations in general terms and is not legal advice. Timelines and specifics have been rolling out in phases — confirm current requirements for your institution with counsel before you rely on any summary, including this one.

How Ivake handles it

Notice and consent are captured at the point a parent submits data, with the purpose recorded alongside and a timestamp, so what was agreed and when is a record rather than a memory. Withdrawal is recorded the same way.

Because one student record replaces the scatter, the question "where is this child's data" has an answer. Access is set by campus, department and role, so a hostel warden sees residents and not marks, and medical or financial information is restricted separately. Every read, change, export and AI action is written to an audit trail with the actor and the previous value — which is what turns a breach question from unanswerable into a report.

Erasure respects the retention you are legally required to keep, so a deletion request does not quietly remove an academic record a board mandates. And Ivake does no advertising, no behavioural profiling and no ad-tech tracking of students, so there is nothing on that front to switch off.

Read the full security position

Book a demo

See Ivake running on your own data

Send us a sample before the call: a term of enquiries, a fee structure, or a class list. We load it and set up your programmes, so you see your own institution on screen rather than a demo account.

  • 45 minutes, your data. Not a generic tour of features.
  • Migration mapped on the call. We show exactly where your current records land.
  • A written rollout plan within two working days, with phases, owners and dates.
  • No pressure to switch everything at once. Most schools and colleges start with one department or one intake.